LWA-2026-7222 confirmed malware

flat-logger-core@1.0.0

Malicious code in flat-logger-core (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer

Analysis

flat-logger-core@1.0.0 is a thin wrapper package (index.js re-exports simple-logger-kit) that pins its sole dependency to a non-registry URL (hxxps://artifacts[.]stg[.]yosiroute[.]com/npm/simple-logger-kit). Installing this package causes npm to fetch and execute arbitrary code from that URL at install time. The package has no repository, no description beyond "Generated package", and its only purpose is to redirect dependency resolution to an attacker-controlled endpoint.

analyzed by
Leitwacht
first seen
Jul 29, 2026, 12:01 PM
analyzed
Jul 29, 2026, 12:02 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.